# Forward logs in CEF format to another host

**URL:** <https://discuss.elastic.co/t/forward-logs-in-cef-format-to-another-host/380226>\
**Category:** Logstash\
**Created:** [July 17, 2025, 8:16pm UTC](https://discuss.elastic.co/t/forward-logs-in-cef-format-to-another-host/380226 "2025-07-17T20:16:06Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![juancamiloll](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juancamiloll/32/110326_2.png) [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Post date:** [July 17, 2025, 8:16pm UTC](https://discuss.elastic.co/t/forward-logs-in-cef-format-to-another-host/380226/1 "2025-07-17T20:16:06Z")

</div>

Hello,

I am currently receiving the logs from fortinet through the integration “Fortinet FortiGate Firewall Logs” which works without problem.

If I log into logstash and run a tcpdump I can see the logs being received.

I am trying to create a .conf file to forward a copy of those logs to another SIEM which requires me to be in CEF format, could you help me to build the .conf?

Is this example correct?

> input {  
> tcp {  
> port =\> 1111  
> }  
> }
> 
> filter {}
> 
> output  
> tcp {  
> host =\> "192.168.1.2"  
> port =\> 2222  
> codec =\> cef {}
> 
> ```auto
> }
> 
> ```
> 
> }
